• Linus Torvalds's avatar
    Merge branch 'mm-readonly-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip · d09e356a
    Linus Torvalds authored
    Pull read-only kernel memory updates from Ingo Molnar:
     "This tree adds two (security related) enhancements to the kernel's
      handling of read-only kernel memory:
    
       - extend read-only kernel memory to a new class of formerly writable
         kernel data: 'post-init read-only memory' via the __ro_after_init
         attribute, and mark the ARM and x86 vDSO as such read-only memory.
    
         This kind of attribute can be used for data that requires a once
         per bootup initialization sequence, but is otherwise never modified
         after that point.
    
         This feature was based on the work by PaX Team and Brad Spengler.
    
         (by Kees Cook, the ARM vDSO bits by David Brown.)
    
       - make CONFIG_DEBUG_RODATA always enabled on x86 and remove the
         Kconfig option.  This simplifies the kernel and also signals that
         read-only memory is the default model and a first-class citizen.
         (Kees Cook)"
    
    * 'mm-readonly-for-linus' of git://git.kernel.org/pub/scm/linux/kernel/git/tip/tip:
      ARM/vdso: Mark the vDSO code read-only after init
      x86/vdso: Mark the vDSO code read-only after init
      lkdtm: Verify that '__ro_after_init' works correctly
      arch: Introduce post-init read-only memory
      x86/mm: Always enable CONFIG_DEBUG_RODATA and remove the Kconfig option
      mm/init: Add 'rodata=off' boot cmdline parameter to disable read-only kernel mappings
      asm-generic: Consolidate mark_rodata_ro()
    d09e356a
pageattr.c 47.3 KB